Bret Settle – API Attack Protection: Don’t Overlook Your #1 Attack Vector
APIs are ubiquitous. Every modern software application uses – or is – an API. Even with this explosive growth, APIs are consistently overlooked in AppSec programs, and attackers are taking advantage of it by increasingly targeting web APIs to gain a foothold, deny access, install bots, escalate privilege and harvest sensitive data. ThreatX co-founder and chief strategy officer, Bret Settle, will discuss the varied types of attack methods used against APIs and share strategies for protecting this growing attack surface.
Transcript
Hello, I'm Brett settle co-founder and chief strategy officer with threat X today. We're going to talk about API protection and minding the Gap in your API security program. We'll start just with the fact that API protection is often an overlooked component.
API has been around for a long long time. But what we've seen just recently is that the number of API collections is really grown exponentially since January of 2017 through 2021. You saw nearly a six to eight times growth pattern and if anything it's growing even faster now.
As the apis have grown and the utilization of the API collections that's grown as is often the case the security and the ability to protect this new technology trend is one of the things that is lagging behind and what's really helped recently is just the number of API breaches that have been notified and shared especially with some really large customers and big breach scenarios for each of these folks. The other thing that we've noted is that you know in 2022 apis are becoming the most frequent attack Vector. We certainly see that with our customer base with the types of attacks that we see on both applications and apis but an extra emphasis really being focused around the apis on the back end and I think some of the analyst agencies like the gardeners and others are also seeing that as well with our customer base.
What is different about apis I mean again a lot of what makes apis valuable is the fact that you can get a lot of reuse it's easy to integrate and for lots of different organizations the ability to expose new features new capabilities and support new business processes comes out of the ability to take these apis and expose it to multiple clients. And along with those capabilities though come some of the risk some things that are more traditional like unauthorized access maybe denials of service or security misconfigurations. But you know a lot of times we get to the point in the conversation where we start talking about.
Well, wait a minute. Those are the same type of risk that we see not just with apis but we see with applications and it's really where we focus in on, you know, some of the differences and the biggest difference is you see with the apis is really around the general lack of disability and awareness. I think most of the Security Professionals that we talk with if you ask them, how many apis do you have?
That's a difficult question for them to answer and the tools that are out there be at an API Gateway or even some of the traditional kind of testing tools. They can provide you some of that visibility but it's so easy to be able to create new apis expose new apis and even apis that you may think are being exposed internally not being exposed externally over time the you know idea or the opportunity to take those apis and say hey that's great capability. Let's now expose that externally significantly.
Images of security profile for it. So again what's different is primarily it's around the lack of visibility and awareness. It's about understanding, you know, the apis what were the initially designed for and what's acceptable usage for those apis and how do you track whether or not the apis are actually being used in the way that they were ultimately designed?
Another kind of key thing that we're seeing in the market here is really around the fact that the attacks have gotten much more complex and specifically what we've seen is the attacks are being distributed across, you know, multiple IPS many of the attacks, especially credential stuffing attacks, maybe account take over attacks. We're seeing them not just in you know hundreds or thousands of ips but sometimes hundreds of thousands of ips as part of the overall attack and this is partially because they can distribute the low and the the attack and stable low the threshold of normal detection. It's also quite honestly a technique they use to really overwhelm the defenses for the organizations that are under attack.
The other thing that we see is that you know, the steps are being really spread out so that the sophistication level and really correlating what you're seeing becomes much much more difficult. They'll do certain steps with a collection of ips they'll do other steps of the different collection of ips and so Having a general understanding of again. What are all these clients doing?
How are they interacting with the apis? Where are potential vulnerabilities and other capabilities there make it a ripe environment for attack and it's really one where we're seeing, you know, the attacker start to focus more and more on the apis because of these conditions. The questions that you really have to ask yourself as you look at this are really around, you know, can I identify when the apis are under attack?
And can I do it in real time? It's a huge challenge correlating all this different information. But if you're doing the correlation after the facts through a correlation engine or a log management type solution, it gives you better Insight, but it certainly doesn't prevent the attack as it's going on.
How do you actually integrate both the detection and the you know correlation that needs to be done to actually block and protect before the damage is done. How do you better understand the type of attacks that are going on for your apis which endpoints are being targeted what techniques are being utilized and again are those attacks because they're underlying vulnerabilities that need to be addressed or are those attacks? Simply the volume and the and the patterns just seen from your attackers, but do you have the appropriate Protections in place?
How do you understand, you know the entire attack surface, as I said before there's literally hundreds of thousands of apis and when you look at the averages for most large Enterprises, the number is typically, you know, two to three to 10x what the security organization is aware of. When you look at the overall attack surface, how do you prioritize how do you better understand what you're seeing in terms of the actual attacks? And then how do you understand the severity of those attacks as well as the likelihood that it would not only cause a breach but a substantial disclosure and information as it comes out and then lastly I mean for my compliance perspective, we always encourage a shift left style of strategy where we focus on identifying the actual Vulnerabilities and then we ensure that you can do the appropriate testing and you can look at whether or not you've built this into your entire ci/cd pipeline, but then assuming that you're doing that you're managing the schemas.
How do you actually ensure that you've got the compliance to ensure that you're meeting the standards that you've been setting within the development organizations? Um on the slide, it really kind of breaks down the difference key areas for what's required for API protection. And while I mentioned before that you can have API gateways and API gateways are very good at managing the authentication the authorization it's great for kind of managing the collections when it comes to the actual security the real time analysis and response.
It's an area where they, you know tend to have less capabilities and and some cases very few capabilities again on the ship left side of the equation understanding the vulnerabilities and ensuring that you're testing against those vulnerabilities extremely important part of the process, but it's also a component where many of the attacks are evolving so quickly as well as the time that it takes to be able to address those vulnerabilities within the code means there's a level of exposure that's out there and you know the need to have a secondary layer of protection for against real-time attacks is extremely important. When you look across these five buckets, these are kind of the pillars that we look at first and foremost as API Discovery and Analysis. So the ability to identify all of the apis and endpoints that are in your environment the ability to understand, you know, not just the apis but the endpoints themselves understanding the methods and parameters for being utilized the types of authentication and air response codes that are being evaluated and then ultimately how do you understand if those the patterns of behavior that you're seeing against those endpoints represent potential risk and vulnerabilities within the organization so a key component of the overall solution is something that can identify and analyze risk via the API Discovery component.
Next the ability to not only evaluate it from a code perspective and from a usage perspective, but the ability to utilize multiple techniques so that as you're seeing those type of attacks the ability to block in real time. So I think you know, a lot of different vendors are using the concepts of AI ml context engines very important to be looking at not just a single transaction but looking at it in full context understanding these multi-step type of attacks seeing the patterns of you know progression that individual attackers are utilizing and part and parcel to just the inspection components. So the ability to do IP interrogation, I'd be fingerprinting other techniques that allow you to ensure that as you're seeing the attacks come through you can actually correlate these attacks that may be coming across multiple IPS other techniques like acting deception tarponing rate limiting and in general just behavioral analytics part and parcel to the ability.
You be able to identify these attacks as they're underway and be able to based on risk quickly determine the blocking thresholds that are required to prevent a full breach from occurring. In part in part and parcel to be able to support that again. It's not just API protection.
It's the ability to see these attacks that maybe starting in the web maybe starting from mobile. Maybe, you know launched at very high thresholds in attempt to overwhelm the resources or at Adidas level and then as I mentioned before certainly bought and the ability to identify these attacks and correlate across multiple IPS. It's all part of the overall platform approach to be able to deliver a complete solution.
Deployment obviously in line gives you the best chance of blocking as it relates to the attacks while they're underway and in real time, but certainly there are needs across a large Enterprise organization to be able to have multiple types of deployment options certainly to support applications and apis that may be hosted maybe in the cloud and on-premise as well. And then lastly but very importantly is the managed service component. There's never enough security resources to go around it's even more complicated when you start talking about application and API security so having an organization, they can not just manage the cloud from a platform perspective really assist in the overall threat analysis the development and enforcement of the policies within the solutions and certainly when under attack having a solution that I can or having an organization that can support you during the attack to ensure that you have the best possible protection put in place as well as their remediation steps that are required.
So again, you know, there's many different components as always security is always done in layers. But when we look at a complete solution across an API environment, these are certainly the Five Pillars that Wheeling into very heavily. And as I said before, you know, it's one thing to define the attack after the fact but really being having the ability to combine each of these capabilities so that you can block in real time is really the ultimate in the solution here as well.
So with that, I just want to thank you for the time today and just say it's a very brief overview from an API protection, but hopefully that gives a you know, a 50,000 foot overview, and certainly if there are other questions or thoughts products is always available to help further this discussion and potentially provide Solutions and capabilities as well. Thank you.





